CWE-295— Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.— MITRE CWE catalog
1,642 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-295page 27 of 33
- CVE-2016-5016MEDIUMCVSS 5.9EG 5.92017-04-24
Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authentication Server) 3.4.1 and earlier, UAA release 12.2 and earlier, PCF (aka Pivotal Cloud Foundry) Elastic Runtime 1.6.x before 1.6.35, and PCF Elastic Runtime 1.7.x bef…
- CVE-2016-1519MEDIUMCVSS 5.9EG 5.92017-04-21
The com.softphone.common package in the Grandstream Wave app 1.0.1.26 and earlier for Android does not properly validate SSL certificates, which allows man-in-the-middle attackers to spoof the Grandstream provisioning server via a crafted …
- CVE-2016-1221MEDIUMCVSS 5.9EG 5.92017-04-21
Jetstar App for iOS before 3.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
- CVE-2016-1210MEDIUMCVSS 5.9EG 5.92017-04-21
The 105 BANK app 1.0 and 1.1 for Android and 1.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
- CVE-2016-1198MEDIUMCVSS 5.9EG 5.92017-04-21
Photopt for Android before 2.0.1 does not verify SSL certificates.
- CVE-2016-1186MEDIUMCVSS 5.9EG 5.92017-04-21
Kintone mobile for Android 1.0.0 through 1.0.5 does not verify SSL server certificates.
- CVE-2016-4840MEDIUMCVSS 5.9EG 5.92017-04-21
Coordinate Plus App for Android 1.0.2 and earlier and Coordinate Plus App for iOS 1.0.2 and earlier do not verify SSL certificates.
- CVE-2016-4832MEDIUMCVSS 5.9EG 5.92017-04-21
WAON "Service Application" for Android 1.4.1 and earlier does not verify SSL certificates.
- CVE-2016-4830MEDIUMCVSS 5.9EG 5.92017-04-21
Sushiro App for iOS 2.1.16 and earlier and Sushiro App for Android 2.1.16.1 and earlier do not verify SSL certificates.
- CVE-2016-4829MEDIUMCVSS 5.9EG 5.92017-04-21
DMM Movie Player App for Android before 1.2.1, and DMM Movie Player App for iPhone/iPad before 2.1.3 does not verify SSL certificates.
- CVE-2016-1184MEDIUMCVSS 5.9EG 5.92017-04-21
Tokyo Star bank App for Android before 1.4 and Tokyo Star bank App for iOS before 1.4 do not validate SSL certificates.
- CVE-2016-4818MEDIUMCVSS 5.9EG 5.92017-04-20
DMMFX Trade for Android 1.5.0 and earlier, DMMFX DEMO Trade for Android 1.5.0 and earlier, and GAITAMEJAPAN FX Trade for Android 1.4.0 and earlier do not verify SSL certificates.
- CVE-2016-9319MEDIUMCVSS 5.9EG 5.92017-03-31
There is Missing SSL Certificate Validation in the Trend Micro Enterprise Mobile Security Android Application before 9.7.1193, aka VRTS-398.
- CVE-2016-9892MEDIUMCVSS 5.9EG 5.92017-03-02
The esets_daemon service in ESET Endpoint Antivirus for macOS before 6.4.168.0 and Endpoint Security for macOS before 6.4.168.0 does not properly verify X.509 certificates from the edf.eset.com SSL server, which allows man-in-the-middle at…
- CVE-2016-2402MEDIUMCVSS 5.9EG 5.92017-01-30
OkHttp before 2.7.4 and 3.x before 3.1.2 allows man-in-the-middle attackers to bypass certificate pinning by sending a certificate chain with a certificate from a non-pinned trusted CA and the pinned certificate.
- CVE-2015-3152MEDIUMCVSS 5.9EG 5.92016-05-16
Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-d…
- CVE-2012-5821MEDIUMCVSS 5.9EG 5.92012-11-04
Lynx does not verify that the server's certificate is signed by a trusted certification authority, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate, related to improper use of a certain GnuTLS functio…
- CVE-2012-5810MEDIUMCVSS 5.9EG 5.92012-11-04
The Chase mobile banking application for Android does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to…
- CVE-2012-2993MEDIUMCVSS 5.9EG 5.92012-09-18
Microsoft Windows Phone 7 does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL server for the (1) POP3, (2) IMAP, or (3) SMTP protocol via…
- CVE-2011-0199MEDIUMCVSS 5.9EG 5.92011-06-24
The Certificate Trust Policy component in Apple Mac OS X before 10.6.8 does not perform CRL checking for Extended Validation (EV) certificates that lack OCSP URLs, which might allow man-in-the-middle attackers to spoof an SSL server via a …
- CVE-2009-2408MEDIUMCVSS 5.9EG 5.92009-07-30
Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X…
- CVE-2008-4989MEDIUMCVSS 5.9EG 5.92008-11-13
The _gnutls_x509_verify_certificate function in lib/x509/verify.c in libgnutls in GnuTLS before 2.6.1 trusts certificate chains in which the last certificate is an arbitrary trusted, self-signed certificate, which allows man-in-the-middle …
- CVE-2023-30517MEDIUMCVSS 5.3EG 5.92023-04-12
Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier unconditionally disables SSL/TLS certificate and hostname validation when connecting to a configured NeuVector Vulnerability Scanner server.
- CVE-2013-10001MEDIUMCVSS 4.8EG 5.92022-05-17
A vulnerability was found in HTC One/Sense 4.x. It has been rated as problematic. Affected by this issue is the certification validation of the mail client. An exploit has been disclosed to the public and may be used.
- CVE-2021-31399MEDIUMCVSS 4.6EG 5.92021-08-13
On 2N Access Unit 2.0 2.31.0.40.5 devices, an attacker can pose as the web relay for a man-in-the-middle attack.
- CVE-2019-5102MEDIUMCVSS 4.0EG 5.92019-11-18
An exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1. When connecting to a remote server, the server's SSL certificate is checked but no action is taken when the certifica…
- CVE-2019-5101MEDIUMCVSS 4.0EG 5.92019-11-18
An exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1. When connecting to a remote server, the server's SSL certificate is checked but no action is taken when the certifica…
- CVE-2017-1200MEDIUMCVSS 3.7EG 5.92019-02-05
IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) does not validate, or incorrectly validates, a certificate.This weakness might allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. The softwa…
- CVE-2017-1265MEDIUMCVSS 3.7EG 5.92018-12-17
IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 does not validate, or incorrectly validates, a certificate. This weakness might allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) tech…
- CVE-2016-2922MEDIUMCVSS 3.7EG 5.92018-08-13
IBM Rational ClearQuest 8.0 through 8.0.1.9 and 9.0 through 9.0.1.3 (CQ OSLC linkages, EmailRelay) fails to check the SSL certificate against the requested hostname. It is subject to a man-in-the-middle attack with an impersonating server …
- CVE-2026-18679MEDIUMCVSS 5.8EG 5.82026-08-12
When kuma-dp is started against an HTTPS control plane and the operator did not pass a CA certificate, the data plane connects with TLS peer verification disabled, and the dataplane authentication token is sent over that unverified connect…
- CVE-2026-52724MEDIUMCVSS 5.8EG 5.82026-07-16
Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, Universal mode kuma-dp connections to an HTTPS control plane disable TLS peer veri…
- CVE-2026-44312MEDIUMCVSS 5.8EG 5.82026-05-14
css_parser is a Ruby CSS parser. Prior to 2.1.0 and 1.22.0, the CSS Parser gem does not validate HTTPS connections, allowing a Man-in-the-Middle (MITM) attacker to inject or modify CSS content when stylesheets are loaded via HTTPS. The con…
- CVE-2026-44363MEDIUMCVSS 5.8EG 5.82026-05-13
MISP modules are autonomous modules that can be used to extend MISP for new services. Prior to 3.0.7, an unsafe remote resource fetching vulnerability existed in MISP Modules expansion modules. The html_to_markdown module accepted arbitrar…
- CVE-2014-0363MEDIUMCVSS v2 5.8EG 5.82014-04-30
The ServerTrustManager component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify basicConstraints and nameConstraints in X.509 certificate chains from SSL servers, which allows man-in-the-middle attackers to spoof se…
- CVE-2012-5824MEDIUMCVSS v2 5.8EG 5.82012-11-04
Trillian 5.1.0.19 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbit…
- CVE-2012-5783MEDIUMCVSS v2 5.8EG 5.82012-11-04
Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field…
- CVE-2011-3061MEDIUMCVSS v2 5.8EG 5.82012-03-30
Google Chrome before 18.0.1025.142 does not properly check X.509 certificates before use of a SPDY proxy, which might allow man-in-the-middle attackers to spoof servers or obtain sensitive information via a crafted certificate.
- CVE-2009-4831MEDIUMCVSS v2 5.8EG 5.82010-04-29
Cerulean Studios Trillian 3.1 Basic does not check SSL certificates during MSN authentication, which allows remote attackers to obtain MSN credentials via a man-in-the-middle attack with a spoofed SSL certificate.
- CVE-2026-22613MEDIUMCVSS 5.7EG 5.72026-02-09
The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potentially allowing an attacker to perform a Man-in-the-middle attack. This security issue has been fixed in the latest firmwar…
- CVE-2025-48393MEDIUMCVSS 5.7EG 5.72025-08-06
The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potentially allowing an attacker to perform a Man-in-the-middle attack. This security issue has been fixed in the latest firmwar…
- CVE-2025-20670MEDIUMCVSS 5.7EG 5.72025-05-05
In Modem, there is a possible permission bypass due to improper certificate validation. This could lead to remote information disclosure, if a UE has connected to a rogue base station controlled by the attacker, with User execution privile…
- CVE-2025-1001MEDIUMCVSS 5.7EG 5.72025-02-21
Medixant RadiAnt DICOM Viewer is vulnerable due to failure of the update mechanism to verify the update server's certificate which could allow an attacker to alter network traffic and carry out a machine-in-the-middle attack (MITM). An att…
- CVE-2025-1002MEDIUMCVSS 5.7EG 5.72025-02-10
MicroDicom DICOM Viewer version 2024.03 fails to adequately verify the update server's certificate, which could make it possible for attackers in a privileged network position to alter network traffic and carry out a machine-in-the-middl…
- CVE-2021-32727MEDIUMCVSS 5.7EG 5.72021-07-12
Nextcloud Android Client is the Android client for Nextcloud. Clients using the Nextcloud end-to-end encryption feature download the public and private key via an API endpoint. In versions prior to 3.16.1, the Nextcloud Android client skip…
- CVE-2026-84032MEDIUMCVSS 5.6EG 5.62026-10-08
IBM Guardium Data Protection 12.2.2 could allow a remote attacker to conduct a man-in-the-middle attack due to improper certificate validation.
- CVE-2026-79967MEDIUMCVSS 5.6EG 5.62026-09-09
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially expl…
- CVE-2026-79642MEDIUMCVSS 5.6EG 5.62026-09-07
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially expl…
- CVE-2026-18257MEDIUMCVSS 5.6EG 5.62026-07-29
Improper validity period check for root issuer certificate in CycloneCrypto cryptographic wrapper of S2OPC allows a certificate issued by this root issuer to be considered trusted
- CVE-2026-24935MEDIUMCVSS 5.6EG 5.62026-02-03
A third-party NAT traversal module fails to validate SSL/TLS certificates when connecting to the signaling server. While subsequent access to device services requires additional authentication, a Man-in-the-Middle (MitM) attacker can inter…
Map vulnerabilities like CWE-295 to your infrastructure
EchelonGraph correlates every CVE — across CWE-295 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →